7 security tips to keep people and apps from stealing your data

Data privacy experts weigh in on how to protect your personal information when on your phone.

Can you really trust the apps on your phone? Researchers discovered that over 1,000 apps that “bent the rules” have horned in on your privacy, even when you told them not to. These apps that gathered precise geolocation data and phone identifiers without the owners’ knowledge. Pretty creepy stuff, especially considering all the private and personal stuff you have on your phone — names, dates, password and credit card information, the location of everywhere you go. Photos of the people in your life.

We reached out to data privacy experts for their top tips to protect your personal data when using apps. Here are their seven suggestions.

Use a password manager

The strongest passwords are random strings of characters. A series of letters, numbers, and symbols in no particular order is less likely to be found in the dictionary and harder for a computer to crack with brute force. The downside is that these complex passwords are much harder to remember.

This is where a password manager app comes in handy. Password managers keep all your passwords in one encrypted and password-protected app. They also generate and remember strong passwords. While apps like Google Chrome and Samsung’s proprietary phone app will offer to save passwords for you, security experts always go to the password manager.

It’s also best to avoid using the same password for multiple accounts. If one account is compromised in a data breach, all the accounts are compromised. With a password manager, each one of your accounts can have a different, complex and hard-to-crack password. Some will even generate passwords for you.

Joe Baker, an IT Systems Administrator at Anderson Technologies, recommends LastPass (download for iOS or Android).

If you’re going to get on a public Wi-Fi network while on your phone instead of using your mobile data, experts suggest using a virtual private network (VPN). A VPN can keep your data from being snooped on by other people lurking on the same public network. They can also mask your data transmissions, avoid filtering and censorship on the internet and allow you to access a wider variety of content around the world.

For our purposes, it can shield you from having to get on a free public network that others can use to gain access to your phone. When looking for a provider, it’s important to research the company to find out if it’s well-known and trustworthy. The Apple App Store and the Google Play Store have dozens of VPN apps that are free, but some have questionable practices, so take care.

Regardless of how frequently you plan to use a VPN, it’s important to read through the service agreement so you know what data might be collected and where it will be stored. See CNET’s guide to the best VPNs.

Be mindful of app permissions

One tip that almost all of the experts mentioned was double-checking which permissions the app asks for. You should also ask yourself whether it makes sense for an app to ask for certain permissions. An app asking for access to data that isn’t relevant to its function is a major warning sign.

“[If] you’re downloading a simple app for a pocket calculator for instance and the app is requesting access to your contact list and location,” said Stephen Hart, CEO of Cardswitcher. “Why would a calculator need to see your contact list and location? Requests like that should ring some alarm bells.”

In addition to paying attention to permissions that you grant to an app, it’s also important to monitor how your phone behaves after you download it. Shlomie Liberow, a technical program manager and security guru at HackerOne, said that drastic changes in your device’s battery life are another red flag since malicious apps can constantly run in the background.

“If after installing an app, you notice your battery life decreasing faster than usual, that may be a tell-tale sign that the app is up to no good and is likely operating in the background,” Liberow said.

Last December, digital security firm Sophos released a list of almost two dozen apps that were found guilty of click fraud resulting in data overages and dramatically draining the device’s battery life.

Research the app or company

While you can’t tell at face value if an app has sinister motives, a quick Google search can supply more information. The experts suggested searching the name of the app and the phrase “data scandal” or “scam.” Hart said the results should tell you if the company has experienced any recent privacy or data leaks.

“This search should also tell you if data breaches are a common occurrence at that company and, if they have experienced any, how they have responded to them,” Hart said. “If the company has been affected several times and done nothing to address the problem, steer clear of the app — it suggests that they aren’t taking the issue seriously.”

Baker said it’s wise to avoid an app if it’s the only one a developer has produced or if the developer was responsible for any other shady apps.

It’s wise to limit the amount of information you share on social media, regardless of what the site asks for on your profile. The more information you share, the more data that’s available to create advertisements for you. Only fill out the absolute minimum amount of information necessary. The more information is at risk in the event of a data breach.

“Smartphone apps are generally more ‘thorough’ when it comes to targeted advertising. There’s even concern among some about those programs accessing your phone’s microphone (presumably for more targeted advertising),” Bobby Kittleberger, head of Legal Software Help, told CNET.

Keep software up to date

Making time to update your smartphone’s operating system (OS) is critical to keeping your data safe, according to Walsh. The updates let you stay a step ahead of hackers and the latest exploits they’re spreading across the internet. Hart suggested adjusting your phone’s settings so it’ll update automatically.

“Think of software updates like vaccinations for your smartphone,” Hart said. “The methods that criminals use to hack into your phone and steal your data are constantly evolving, so the ways that we protect our smartphones need to evolve too.”

Only download apps from Google and Apple’s stores

Not all the apps in the App Store or the Google Play store are 100% trustworthy, but experts still say you should only download from the official stores, rather than side-load an app.

“Apps available on these platforms will have been vetted to ensure that they meet a standard quality of data protection and will also be required to produce a dedicated privacy policy for you, telling you just how they protect your data,” Hart told CNET.

Downloading an app from unofficial or insecure sites increases the risk of ransomware, malware, spyware and trojan viruses infecting your device, according to Walsh. He says in the worst-case scenario, the hacker can take full control of your device.